GHSA-frqx-jfcm-6jjr

Source
https://github.com/advisories/GHSA-frqx-jfcm-6jjr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/05/GHSA-frqx-jfcm-6jjr/GHSA-frqx-jfcm-6jjr.json
Aliases
Published
2023-05-26T19:39:03Z
Modified
2023-11-08T04:12:40.056905Z
Details

Impact

A malformed proposed entry of the intoto/v0.0.2 type can cause a panic on a thread within the Rekor process. The thread is recovered so the client receives a 500 error message and service still continues, so the availability impact of this is minimal.

Patches

This is fixed in v1.2.0 of Rekor.

Workarounds

No

References

Discovered by OSS-Fuzz

References

Affected packages

Go / github.com/sigstore/rekor

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.2.0